Age VerificationOnline Safety ActRegulatory Compliance

UK Steam Update! Age Verification Feature Updated to Comply with the Online Safety Act

英国Steam更新!年龄验证功能更新以符合《在线安全法案》

January 8, 2026
0 views

Summary

Valve announced that starting August 29, 2025, Steam in the UK will implement a credit-card-based age verification system to comply with the UK Online Safety Act (OSA). All UK users who wish to access “mature-rated” game store pages and related community content must opt in by adding a valid credit card to their account. The system verifies the card through a £0 authorization and bank confirmation, and the verification remains valid as long as the card stays on file. Valve explains that this approach follows Ofcom’s guidance that credit-card checks are an effective age-assurance method, and it protects user privacy better than facial scans or ID uploads. Keeping a card on file also discourages account sharing.

Recently, Valve updated its age verification feature for the UK region, effective August 29, 2025, to comply with the UK Online Safety Act (OSA) regulatory requirements. The core requirement of the new policy is clear: all Steam users located in the UK who wish to access store pages for games rated “mature” and their associated community hubs must first complete a one-time age verification process. This is an opt-in process requiring users to actively choose to participate, rather than being enabled by default.

Valve's verification mechanism for UK users is singular and mandatory: adding a valid credit card to their Steam account. Long-time users who already have a credit card linked to their account will face no new restrictions and retain unrestricted access to relevant content.

The specific verification process includes: Users must log in to their Steam account, navigate to the “Account Details” page, and click the “Add Payment Method” button. The system then guides users to enter their credit card details, including card type, card number, CVV security code, expiration date, cardholder name, and billing address. After submitting this information, the system triggers a £0 authorization transaction and initiates a verification challenge based on the issuing bank's policy—such as receiving a one-time password (OTP) via mobile phone or confirming within the bank's mobile app.

Once this process is successfully completed, the user's account is considered “age verified.” The validity of this verification status is directly tied to the credit card's binding status—as long as the credit card remains stored in the account, the verification remains active. This is not a one-time identity confirmation but a continuous status maintenance. If the user removes the credit card, their access to adult content may be revoked.

Valve has provided a clear official explanation for its chosen single verification method, with its core rationale centered on three key aspects: compliance with regulatory guidance, maximizing user privacy protection, and enhancing account security.

First, Valve explicitly states that its decision is based on guidance from Ofcom, the UK's independent regulator for communications. In its guidance on the Online Safety Act, Ofcom identifies credit card verification as an “effective age assurance measure.” This classification stems from UK financial regulations: individuals must be at least 18 years old to legally apply for and obtain a credit card. Consequently, credit card issuers already bear a legal obligation to verify applicants' ages before issuing cards. By leveraging this existing, heavily regulated verification outcome, Steam can indirectly confirm user ages, thereby meeting regulatory requirements.

Second, Valve prioritizes user privacy protection at a strategic level. Valve emphasizes that credit card verification “maximizes user privacy” compared to other potential age verification methods (such as facial scans or uploading government-issued IDs). The key lies in the fact that the data processed during the entire verification process is identical to the data processed when millions of users make routine purchases on Steam or conveniently store payment information. This means the verification process itself does not disclose any new information about users' content preferences to payment providers or any other third parties.

Finally, Valve believes that storing credit cards as a persistent payment method within accounts also serves as an “additional deterrent” against multiple users sharing the same Steam account to circumvent age verification. This design increases the complexity and risk of account sharing, thereby reinforcing the effectiveness of age restrictions to some extent.

Valve's chosen strategy profoundly reflects its core considerations when addressing regulatory pressures. Faced with potential fines of up to 10% of global revenue under the Online Safety Act and the data breach risks other platforms encounter by adopting third-party biometric or ID verification services, Valve clearly prioritizes avoiding data security risks and preserving user trust.

Reviewing its historical actions in other regulated markets (such as Germany), Valve tends to directly block content rather than handle sensitive national identity information. Thus, the credit card verification solution represents a “path of least resistance” for data security. It not only leverages existing, secure, and compliant internal systems but also ‘outsources’ primary age verification responsibility to financial institutions, thereby minimizing Valve's own legal and data processing liabilities. This is a deliberate strategic choice designed to avoid creating databases of sensitive user information—what security experts term data “honey pots.”

中文原文

近日,Valve 更新英区年龄验证功能并于2025 年 8 月 29 日生效,以符合英国在线安全法案 (OSA)的监管要求。新政策的核心要求十分明确:所有位于英国的Steam用户,若希望访问被评为“成人级”(mature-rated)的游戏商店页面及其相关的社区中心,必须首先完成一次性的年龄验证流程。这是一个需要用户主动选择加入的“选择性进入”(opt-in)过程,而非默认开启。

Valve为英国用户提供的验证机制是单一且强制性的:将一张有效的信用卡添加至其Steam账户。对于那些账户中早已绑定了信用卡的资深用户,他们将不会受到任何新的限制,可无限制地访问相关内容。

具体的验证流程包括:用户需要登录自己的Steam账户,进入“账户详情”页面,点击“添加支付方式”按钮。随后,系统会引导用户填写信用卡详细信息,包括卡类型、卡号、CVV安全码、有效期、持卡人姓名及账单地址。提交信息后,系统会触发一笔金额为0英镑的授权交易,并根据发卡银行的策略,向用户发起一项验证挑战,例如通过手机接收一次性密码(OTP)或在银行的移动应用中进行确认 。

一旦该流程成功完成,用户的账户便被视为“已通过年龄验证”。此验证状态的有效性与信用卡的绑定状态直接挂钩——只要该信用卡持续存储在账户中,验证便一直有效 。这并非一次性的身份确认,而是一种持续性的状态维持,如果用户移除了信用卡,其访问成人内容的权限可能会随之失效。

Valve公司为其选择的单一验证方式提供了清晰的官方解释,其核心逻辑围绕着遵守监管指导、最大化保护用户隐私以及增强账户安全性三个层面

首先,Valve明确指出,其决策是基于英国网络安全独立监管机构Ofcom的指导意见。Ofcom在其关于《在线安全法》的指南中,将信用卡检查认定为一种“高效的年龄保障措施”。这一判断的依据在于英国的金融法规:个人必须年满18周岁才能合法申请并获得信用卡。因此,信用卡发行机构在发卡前已承担了核实申请人年龄的法定义务。通过利用这一现有的、受严格监管的验证结果,Steam得以间接确认用户年龄,从而满足法规要求。

其次,Valve将用户隐私保护置于极高的战略位置。Valve公司强调,与其他潜在的年龄验证机制(如面部扫描、上传政府颁发的身份证件等)相比,信用卡验证“最大限度地保护了用户隐私”。其关键在于,整个验证过程处理的数据与数百万用户在Steam上进行日常购物或为方便而存储支付信息时所处理的数据完全相同。这意味着,验证过程本身不会向支付提供商或其他任何第三方泄露关于用户内容偏好的新信息
最后,Valve认为,将信用卡作为一种持续的支付方式存储在账户中,还能起到“额外的威慑作用”,以防止多人共享同一个Steam账户来规避年龄验证 。这种设计增加了账户共享的复杂性和风险,从而在一定程度上强化了年龄门槛的有效性。

Valve选择的策略深刻地反映了其在应对监管压力时的核心考量。面对《在线安全法》可能带来的高达全球营业额10%的巨额罚款,以及其他平台因采用第三方生物识别或ID验证服务而面临的数据泄露风险,Valve显然将规避数据安全风险和维护用户信任放在了首位。

回顾其在其他受监管市场(如德国)的历史行为,Valve倾向于直接屏蔽内容,而非处理敏感的国民身份信息。因此,信用卡验证方案可以被视为一条在数据安全层面“阻力最小的路径”。它不仅利用了现有、安全且合规的内部系统,还将主要的年龄核实责任“外包”给了金融机构,从而将自身的法律和数据处理责任降至最低。这是一种深思熟虑的战略抉择,旨在避免创建被安全专家称为数据“蜜罐”(honey pots)的用户敏感信息数据库。

分享文章

相关文章

General

【Weekly Gaming Law】Lawyers Comment on miHoYo’s Anti-Fraud Actions; Infringing “Reskinned” Game Ordered to Pay RMB 5 Million

【每周游戏法】律师评米哈游反舞弊;侵权游卡被判赔500万

This weekly update examines three recent legal developments in the gaming industry: miHoYo’s anti-fraud enforcement and supplier blacklist measures; a “reskin” infringement case involving a Three Kingdoms-themed card game resulting in a RMB 5 million damages award based on unfair competition; and Roblox’s launch of AI-powered interactive content generation tools. The article outlines the legal considerations arising from supply chain compliance, the boundary between public domain materials and protectable game design, and the intellectual property and compliance implications of AI-generated interactive content within UGC platforms.

0 views
General

How to Build Official Game Payment Systems in a Compliant Manner (Part II): Overseas

游戏官方支付如何合规搭建(二)海外篇

Against the backdrop of a global economic slowdown and evolving regulatory scrutiny over major app distribution platforms, an increasing number of overseas-oriented game companies are exploring the establishment of official website top-up platforms to reduce reliance on channel commissions. Building on the prior discussion of platform policies regarding payment redirection and third-party payment access, this article reviews practical cases of official website payment models adopted by several game companies, including their login mechanisms, purchasable content, regional availability, and qualification disclosures. Based on these practices, it outlines compliance considerations that overseas game companies should focus on when constructing official website payment systems, particularly in relation to account management, price display, promotional methods, and refund policy design across different jurisdictions.

6 views
General

EU’s DMA Enforcement Push: Apple and Epic Games Reach Temporary Truce

欧盟DMA强监管,苹果与Epic Games暂时握手言和

Since 2020, Apple and Epic Games have been locked in a global antitrust dispute over App Store policies. While Epic lost its U.S. lawsuit, it continued its resistance through noncompliance, resulting in a developer account ban. However, the dynamics shifted with the EU Digital Markets Act (DMA) coming into force on March 6, 2024. Epic reported that Apple, under pressure from the European Commission, agreed to reinstate its developer account in the EU. The DMA’s provisions, especially Article 5(3) and Article 6(4), require gatekeepers like Apple to allow third-party app stores and payment systems on iOS. Apple’s attempt to ban Epic amid DMA implementation triggered regulatory attention, leading to rapid Commission intervention. This incident not only highlights the DMA’s enforcement teeth but also signals a broader shift in platform governance within the EU. For global developers and digital exporters, especially those dependent on app store distribution, DMA compliance represents a strategic inflection point. Non-compliance risks include fines of up to 10–20% of global turnover, exemplified by the €1.84 billion fine Apple recently faced. As more third-party app stores (e.g., Mobivention, MacPaw) emerge, the EU’s digital market is poised for structural transformation.

5 views